* [PATCH] staging: greybus: bootrom: fix null pointer dereference in get_firmware
@ 2026-10-05 6:34 Marinela Tatiana Selseth
2026-10-05 8:22 ` Johan Hovold
0 siblings, 1 reply; 2+ messages in thread
From: Marinela Tatiana Selseth @ 2026-10-05 6:34 UTC (permalink / raw)
To: vaibhav.sr, mgreer, johan, elder, gregkh
Cc: greybus-dev, linux-staging, linux-kernel, Marinela Tatiana Selseth
Automated static analysis via Coccinelle uncovered a potential null
pointer dereference and uninitialized stack pointer vulnerability
inside gb_bootrom_get_firmware().
The routine evaluates whether a firmware transmission sequence is
complete at its trailing 'queue_work:' label by checking if the
transfer bounds match 'fw->size'.
When this label is reached the 'fw' can be uninitialized or NULL.
Both scenarios expose the kernel to critical memory faults or null
pointer panics.
Fix these dual vulnerability paths by initializing the 'fw' pointer
to NULL at its top-level definition block and introducing an
explicit short-circuit guard condition to safely gate the
trailing size evaluation.
Assisted-by: Gemini
Signed-off-by: Marinela Tatiana Selseth <marinela.selseth@firmwaredesign.org>
---
drivers/staging/greybus/bootrom.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/staging/greybus/bootrom.c b/drivers/staging/greybus/bootrom.c
index 83921d90c322..cead4b505f6c 100644
--- a/drivers/staging/greybus/bootrom.c
+++ b/drivers/staging/greybus/bootrom.c
@@ -241,7 +241,7 @@ static int gb_bootrom_firmware_size_request(struct gb_operation *op)
static int gb_bootrom_get_firmware(struct gb_operation *op)
{
struct gb_bootrom *bootrom = gb_connection_get_data(op->connection);
- const struct firmware *fw;
+ const struct firmware *fw = NULL;
struct gb_bootrom_get_firmware_request *firmware_request;
struct device *dev = &op->connection->bundle->dev;
unsigned int offset, size;
@@ -298,7 +298,7 @@ static int gb_bootrom_get_firmware(struct gb_operation *op)
queue_work:
/* Refresh timeout */
- if (!ret && (offset + size == fw->size))
+ if (fw && !ret && (offset + size == fw->size))
next_request = NEXT_REQ_READY_TO_BOOT;
else
next_request = NEXT_REQ_GET_FIRMWARE;
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] staging: greybus: bootrom: fix null pointer dereference in get_firmware
2026-10-05 6:34 [PATCH] staging: greybus: bootrom: fix null pointer dereference in get_firmware Marinela Tatiana Selseth
@ 2026-10-05 8:22 ` Johan Hovold
0 siblings, 0 replies; 2+ messages in thread
From: Johan Hovold @ 2026-10-05 8:22 UTC (permalink / raw)
To: Marinela Tatiana Selseth
Cc: vaibhav.sr, mgreer, elder, gregkh, greybus-dev, linux-staging,
linux-kernel
On Mon, Oct 05, 2026 at 01:34:54AM -0500, Marinela Tatiana Selseth wrote:
> Automated static analysis via Coccinelle uncovered a potential null
> pointer dereference and uninitialized stack pointer vulnerability
> inside gb_bootrom_get_firmware().
Please check the archives to see why coccinelle is wrong.
> The routine evaluates whether a firmware transmission sequence is
> complete at its trailing 'queue_work:' label by checking if the
> transfer bounds match 'fw->size'.
> When this label is reached the 'fw' can be uninitialized or NULL.
> Both scenarios expose the kernel to critical memory faults or null
> pointer panics.
>
> Fix these dual vulnerability paths by initializing the 'fw' pointer
> to NULL at its top-level definition block and introducing an
> explicit short-circuit guard condition to safely gate the
> trailing size evaluation.
>
> Assisted-by: Gemini
Also, LLM assisted patches are rejected for staging (again, see the
archives).
> Signed-off-by: Marinela Tatiana Selseth <marinela.selseth@firmwaredesign.org>
Johan
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 8:22 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 6:34 [PATCH] staging: greybus: bootrom: fix null pointer dereference in get_firmware Marinela Tatiana Selseth
2026-10-05 8:22 ` Johan Hovold
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®